Redesigning Account Settings: A Privacy-First Approach for a Health App
Tech · 5 min read
Previously, the app had a long list of granular toggles buried in settings with legalistic labels that users ignored or misinterpreted. Compliance flagged this as a risk and customer interviews revealed users felt uncertain about sharing sensitive data. The product team adopted a privacy-first principle: make privacy decisions meaningful, understandable, and reversible.
Design changes included grouping settings by intent (Sharing, Personalization, Medical Data), replacing binary toggles with staged consent cards that explained trade-offs in plain language, and introducing a 'Privacy Snapshot' that summarized what was shared and with whom. Critical choices used confirmation modals with examples of downstream effects (e.g., 'Turning this off will limit personalized care suggestions'). The team also implemented a one-tap export and delete workflow to align with user control expectations.
After rollout, privacy-related support tickets decreased by 29% and the app's trust score in surveys improved by 18 points. Importantly, opt-out rates for nonessential personalization features were higher than anticipated, but engagement among users who remained opted-in increased—suggesting clearer consent led to more meaningful, intent-driven personalization. The team concluded that transparent design reduces friction and builds long-term trust rather than sacrificing features for blanket defaults.